NIST 800-171 · System and Communications Protection

Requirement 3.13.8

SPRS weight
SPRS weight: 3
POA&M eligibility
Not POA&M-eligible
Assessment objectives
3 assessment objectives

Official requirement text

Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.13.8[a]cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified.
  2. 3.13.8[b]alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified.
  3. 3.13.8[c]either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.